cbcvebase.
CVE-2025-12464
published 2025-10-31

CVE-2025-12464: A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and…

PriorityP427medium6.2CVSS 3.1
AVLACLPRNUINSUCNINAH
EPSS
0.17%
6.5th percentile
A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and moved to the net core code. The issue stems from the device's receive code still being able to process a short frame in loopback mode. This could lead to a buffer overrun in the e1000_receive_iov() function via the loopback code path. A malicious guest user could use this vulnerability to crash the QEMU process on the host, resulting in a denial of service.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 1:10.1.3+ds-1 (forky)qemu 1:10.1.3+ds-1 (forky)
msrcazl3_qemu_8.2.0-21_on_azure_linux_3.0
msrcazl3_qemu_8.2.0-23_on_azure_linux_3.0
msrcazl3_qemu_8.2.0-25_on_azure_linux_3.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_kernel_5.4.91-3_on_cbl_mariner_1.0
qemuqemu>= 0 < 1:10.0.7+ds-0+deb13u11:10.0.7+ds-0+deb13u1
qemuqemu>= 0 < 1:10.1.3+ds-11:10.1.3+ds-1
qemuqemu>= 0 < 1:6.2+dfsg-2ubuntu6.281:6.2+dfsg-2ubuntu6.28
qemuqemu>= 0 < 1:8.2.2+ds-0ubuntu1.131:8.2.2+ds-0ubuntu1.13
qemuqemu>= 0 < 1:10.1.0+ds-5ubuntu2.41:10.1.0+ds-5ubuntu2.4

CVSS provenance

nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.2MEDIUM
vendor_msrc6.7MEDIUM
vendor_debian6.2LOW
vendor_redhat6.2MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.